Impact
An Improper Neutralization of Escape, Meta, or Control Sequences vulnerability exists in Dell Secure Connect Gateway 5.0 Appliance and Application. The flaw allows attacker‑supplied data to be interpreted as executable or interpretable content because the input is not properly escaped. This can enable the injection of malicious payloads that may be presented to users, leading to phishing attempts.
Affected Systems
Dell Secure Connect Gateway 5.0 Appliance versions older than 5.36.00.16 and Dell Secure Connect Gateway 5.0 Application versions older than 5.36.00.00 are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium risk range, and the EPSS score is not available, indicating insufficient evidence of public exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an unauthenticated remote attacker sending crafted requests; no local privilege escalation is required. Exploitation could result in users interacting with phishing content generated by the improperly neutralized input.
OpenCVE Enrichment